CompTIA PenTest+ (PT0-003)Attacks and ExploitsHard

A tester compromises a domain controller and uses Mimikatz to extract the krbtgt account's NTLM hash via a DCSync attack. The tester then forges a Kerberos ticket-granting ticket with arbitrary group memberships and a ten-year expiration, allowing continued domain admin access even after all user passwords are reset. Which attack technique does this describe?

  1. AKerberoasting
  2. BPass-the-hash attack
  3. CGolden ticket attack
  4. DSilver ticket attack
Show answer & explanation

Correct answer: C. Golden ticket attack

Forging a TGT using the krbtgt account's hash creates a golden ticket, granting near-unlimited, long-lived access to any resource in the domain regardless of subsequent password changes, since the krbtgt key controls the entire Kerberos trust.

Why the other options are wrong

  • A. Kerberoasting cracks service account passwords from requested TGS hashes, not forging a TGT with krbtgt.
  • B. Pass-the-hash reuses an NTLM hash for authentication, not Kerberos ticket forgery.
  • D. A silver ticket forges a TGS using a service account's hash, granting access to only that specific service, not domain-wide access.

Golden Ticket Attack

A Kerberos attack where an adversary uses the krbtgt account's NTLM hash to forge a Ticket Granting Ticket, granting persistent, domain-wide access that survives password resets.

  • Requires the krbtgt hash, often obtained via DCSync
  • Grants access to any service in the domain as any user
  • Remediated by resetting the krbtgt password twice

Memory trick: Golden ticket = the master key to the whole Kerberos kingdom

More Attacks and Exploits questions